All insightsRoadmap · v1 · 2026
The QA Engineer Roadmap for the AI age A career path, not a catalogue. Start with a 22-topic starter path you can finish, then branch into automation, delivery, a specialism, or testing AI systems. You do not need all 123 topics to get a job.
123 topics in the full library9 stages123 guides written
How to use this roadmap New to QA: choose New to QA under starting point, or stay on the starter path and begin with Stage 1.Manual QA moving into automation: choose Manual QA → automation under starting point.Already automating: choose Automation → SDET, or Core only and then Stage 5.Complete Core first. Use Go deeper for your chosen path. Open Reference when you need it. Mark a topic complete only after doing its practice task, or producing the proof described in the guide. Choose your starting point
Core Required for this stage.
Go deeper Choose this when it supports your role or specialisation.
Reference Know what it is; return when you need it. Stage 1 QA foundations 10 Stage 2 Working on a product team 16 Stage 3 Technical foundations 12 Stage 4 Test automation 13 Stage 5 CI, delivery, and reliability 11 Stage 6a Specialise: performance, security, accessibility 13 Stage 6b Specialise: AI as your instrument 15 Stage 6c Specialise: testing AI systems 25 Throughout Communication, risk, and career growth 8 Or browse every topic as one list
Choose your starting point
Starter path Twenty-two topics. A first visit you can actually finish. Core only Required topics for every stage. Skip Go deeper and Reference. New to QA Foundations and team practice, plus how to talk about risk. Manual QA → automation Technical foundations, then a small trusted suite. Automation → SDET Architecture, the pipeline, and reliability after merge. QA → lead Strategy, review, coaching, and proof of work. Performance, security, accessibility The non-functional specialisms. Pick one and go deep. AI quality Using AI to test, then testing the AI systems teams now ship. Full map All 123 topics, as a reference library.
Stage 1 QA foundations The thinking that survives every tooling shift: risk, oracles, and how to tell whether something is actually right.
After this stage, you can Explain quality as risk, design a small set of cases, and run a structured exploratory session.
Build this A one-page risk-based test approach for a feature you already know.
Typical roles Junior QA, manual tester, anyone new to the craft.
About 2–3 weeks at five hours a week 5 topics on this path
Milestone 1 Write a risk-based test approach and a reproducible bug report.
Stage 2 Working on a product team How testing actually happens on a team: the sprint, the regression cycle, and the documents everybody asks you to produce.
After this stage, you can Sit in refinement, write cases someone else can run, file a bug that gets fixed, and sign off a release honestly.
Build this A reproducible bug report plus a short test plan for one upcoming release.
Typical roles QA engineer on a product squad.
About 3–4 weeks at five hours a week 5 topics on this path
Stage 3 Technical foundations Technical skills that make modern QA work easier. A tester who can read a diff can review what an agent wrote.
After this stage, you can Read a pull request, hit an API, check a database row, and diagnose a UI failure from DevTools.
Build this A short write-up of a real bug you traced through HTTP, the DOM, or SQL.
Typical roles QA engineer moving toward automation.
About 4–6 weeks at five hours a week 5 topics on this path
Milestone 2 Validate an API response and a database result yourself.
Stage 4 Test automation Writing a test is the commodity half. Designing a suite that is still trusted in three years is not.
After this stage, you can Build a small Playwright or API suite that other people can run, and explain why a flake happened.
Build this A public or internal suite covering one user journey and one API contract.
Typical roles Automation QA, SDET in training.
About 4–6 weeks at five hours a week 3 topics on this path
Milestone 3 Build a small Playwright or API suite in Git.
Stage 5 CI, delivery, and reliability Skills that help QA work scale beyond a local test suite. Everything here is about a suite surviving contact with CI.
After this stage, you can Put the suite in the pipeline, keep it under a runtime budget, and be useful when production breaks.
Build this The same suite running in CI, with a note on what a red build should block.
Typical roles SDET, quality engineer.
About 3–5 weeks at five hours a week 1 topic on this path
Milestone 4 Run that suite in CI and diagnose a failed run.
Stage 6a Specialise: performance, security, accessibility Performance, security, accessibility and privacy: areas where failures can have the highest customer and business impact, and where unsupervised AI is weakest.
0 topics on this path
These topics are not on Starter path. Switch path, or open Full map.
These topics are not on Starter path. Switch path, or open Full map.
Stage 6c Specialise: testing AI systems Many teams are beginning to ship large-language-model features, and almost nobody knows how to test one. The largest layer here, on purpose.
0 topics on this path
These topics are not on Starter path. Switch path, or open Full map.
Throughout Communication, risk, and career growth What stays scarce once writing tests gets cheap. Start these skills in Stage 1 and deepen them as you go; they are not a final exam.
After this stage, you can Describe launch risk in language a product manager will act on, and show work a hiring manager can open.
Build this A public write-up, a small suite, or a post-mortem that a stranger could follow.
Typical roles Senior QA, QA lead, quality engineer, AI quality.
About Ongoing, a little in every stage at five hours a week 3 topics on this path
Start Every topic, in order The whole library on one page, whichever path you picked above. 123 topics across 9 stages — the ones with a guide open; the rest are on the map and not yet written.
Stage 2 Working on a product teamTesting inside a sprint, day by day Core Refinement, acceptance criteria and the three amigos Core Writing test cases someone else can run Core Writing a bug report that gets fixed Core Defect triage: severity, priority and who decides Go deeper Running a regression cycle Core Choosing what goes in the regression pack Go deeper Smoke, sanity, and user acceptance testing (UAT): who runs what, and when Reference Writing a test strategy Core Writing a test plan Core Entry criteria, exit criteria and the definition of done Go deeper Estimating test effort Go deeper Traceability: requirement to test to result Go deeper The test summary report and release sign-off Go deeper Test management: Jira, Xray, TestRail, Zephyr Reference Drafting QA documents with AI Core Stage 3 Technical foundationsOne language, properly: TypeScript or Python Core Git, branching and pull-request review Core Reading a codebase; reading a diff Core HTTP and REST: status codes and headers Core GraphQL and gRPC for testers Go deeper Auth: sessions, JSON Web Token (JWT), OAuth2, OpenID Connect (OIDC) Go deeper SQL and the data layer Core Queues, events and async systems Go deeper The browser platform: DOM, events, rendering Core DevTools and network debugging Core Containers: Docker and Compose Go deeper Cloud basics: environments, config, secrets Go deeper Stage 4 Test automationThe pyramid, the trophy, and choosing per system Core Test architecture: fixtures, builders, page objects Core Playwright as the default web stack Core Selenium and Cypress literacy Reference API testing and schema validation Core Contract testing with Pact Go deeper Mocking and service virtualisation Go deeper Mobile: Appium, Espresso, XCUITest, Maestro Go deeper Component and unit testing Go deeper Visual and snapshot regression Go deeper Test data: factories, seeding, anonymisation Core Flakiness: causes, quarantine, retry policy Core Determinism: clocks, seeds, network control Core Stage 5 CI, delivery, and reliabilityStage 6a Specialise: performance, security, accessibilityPerformance testing: k6, JMeter, Gatling Core Thinking in percentiles, not averages Core Load profiles: soak, spike, stress, breakpoint Go deeper Frontend performance and Core Web Vitals Go deeper Security: the OWASP Top 10 for web apps Core OWASP API Security Top 10 Go deeper Static, dynamic, and software-composition analysis (SAST, DAST, SCA) Go deeper Supply chain: software bill of materials (SBOM) and dependency risk Go deeper Secrets management Go deeper Accessibility: WCAG 2.2, axe, and screen readers Core Accessibility law: the European Accessibility Act Reference Privacy in test data: GDPR and India’s DPDP Act Go deeper Resilience and chaos basics Reference Stage 6b Specialise: AI as your instrumentStage 6c Specialise: testing AI systemsAnatomy of an LLM feature Core Retrieval-augmented generation (RAG) systems explained for testers Core Agents: planning, tool calls, memory, loops Core Why assertions break: non-determinism and drift Core Evals: the new test suite Core Building a golden dataset Core Using a large language model as a judge, and its failure modes Core Rubrics, scoring and inter-rater agreement Go deeper Offline evals vs online evals Go deeper Groundedness, faithfulness, hallucination rate Core Task success and tool-call accuracy Core RAG testing: retrieval precision and recall Core Chunking, ranking and citation checking Go deeper Agent trajectory testing Core Tool misuse and loop detection Go deeper Prompt injection: direct Core Prompt injection: indirect Core Jailbreaks and data exfiltration Go deeper Excessive agency and blast radius Go deeper OWASP Top 10 for large-language-model applications Core OWASP Top 10 for agentic applications Core Red-teaming an AI feature Go deeper Guardrails, refusals and over-refusal Go deeper The model-bump problem Core AI governance: the EU AI Act, ISO 42001, and the NIST AI Risk Management Framework Go deeper Throughout Communication, risk, and career growthHow this stays current The roadmap is a living document, not a snapshot. New topics are added as the field moves, and guides are revised when the thing they describe changes. A topic added after launch is flagged New topic on the map. Revisions to existing guides are not badged on every card; they show up here and on the guide itself. The version stamp moves once a year.
Start somewhere
Build the roadmap in a real workspace The roadmap describes where a QA practice is going. Tesbo is where you run it. Create a free account and start with whichever layer your team is stuck on — the Launch plan is free forever.
Start free